Hetzner发布博文介绍其云计算网络栈的历史演变与技术架构1。公司从2011年的vServers产品开始,采用Linux桥接和静态路由方案,支持1Gb/s链路速率,可容纳约25,000个实例1。2015年9月推出第二代产品,引入Ceph超融合架构和BGP动态路由,并于2016年升级至2×10Gb/s链路,支持的实例数量增至约50,000个1。
2018年Hetzner Cloud正式推出,标志着网络架构的重大转变1。该产品放弃了NAT配置,改采直接IPv4路由模式1。2019年7月,公司引入Open vSwitch数据平面和VXLAN私有网络支持1,并于2021年3月推出基于Open vSwitch和netfilter的状态防火墙1。
当前架构通过两条10Gb/s上行链路采用LAG/LACP聚合或BGP原生路由实现连接1。Hetzner自研了Flusskrebs控制器项目,用Python编写并提供REST API接口,负责配置OpenFlow流规则以及管理公网和私有网络的DHCP服务1。云防火墙基于Linux netfilter连接跟踪机制,对每台服务器设置80,000个活跃并发连接上限,由ctcount项目负责追踪表条目管理1。每个虚拟机可配置1个公网接口和最多3个私有网络接口1。
尽管现有网络栈已支持超过百万台云服务器,但Hetzner表示已触及性能瓶颈,正在开发下一代自研网络栈以增强可扩展性、韧性和灵活性1。
Hetzner has published a detailed account of its cloud computing network infrastructure's development and current design. 1 The company's networking capabilities have undergone significant transformation since its early virtualization offerings, progressing from basic Linux bridging and static routing to a sophisticated multi-layered architecture supporting over one million cloud server instances. 1
The evolution began with Hetzner vServers launched in 2011, which relied on Linux bridges and static routing over 1 Gb/s connections to serve approximately 25,000 instances. 1 A second-generation platform introduced in September 2015 marked a substantial shift, incorporating a converged Ceph architecture with dynamic BGP routing and 1:1 NAT-based IPv4 configuration, later upgraded to dual 10 Gb/s links by 2016 to support roughly 50,000 instances. 1 The flagship Hetzner Cloud service, launched in 2018, abandoned NAT in favor of direct IPv4 routing, with Open vSwitch data plane functionality and VXLAN private network support added in July 2019. 1 A stateful firewall based on Open vSwitch and netfilter was introduced in March 2021. 1
The current network stack leverages two 10 Gb/s uplink connections aggregated through LAG/LACP or native BGP routing, allowing each virtual machine to maintain one public interface and up to three private network interfaces. 1 Hetzner developed an in-house controller called Flusskrebs, written in Python and exposing a REST API that configures OpenFlow flow rules while managing DHCP for both public and private network segments. 1 Cloud firewall protection operates through Linux netfilter connection tracking, enforcing a per-server limit of 80,000 active concurrent connections with connection table entries managed by the ctcount project. 1 Despite these advances, Hetzner has acknowledged reaching performance bottlenecks and is actively developing a next-generation network stack designed to enhance scalability, resilience, and operational flexibility. 1
评论
还没有评论,欢迎留下第一条。